Splunk Search

How to custom sort by column headers

DEADBEEF
Path Finder

I have a table that shows the number of logs by severity over each host.  I want to be able to rearrange the severity columns into a specific order but can't figure out how.  I tried using custom sort field via eval but didn't seem to work.

Current SPL

 

index=foo sourcetype=logs
| chart count over server by severity

 


Current Table Order

 

server   major   info   critical    minor
serverA   5       10       8          6
serverB   22       5       13         9

 

 

Desired Table Order

 

server   critical  major   minor  info
serverA   8         5       6      10
serverB   13        22      9       5

 

Labels (2)
Tags (3)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

use table command to re arrange table header:

 

| table server critical major minor info

————————————
If this helps, give a like below.

View solution in original post

thambisetty
SplunkTrust
SplunkTrust

use table command to re arrange table header:

 

| table server critical major minor info

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...